Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.3% | — | Microsoft Visual Studio Code Kubernetes Tools | 13/4/2021 | 17/6/2026 | Visual Studio Code Kubernetes Tools Remote Code Execution Vulnerability | |
| Modificada | Alta (7.4) | 1.3% | — | Redhat Kubernetes-clientRedhat A-mq OnlineRedhat Build OF QuarkusRedhat Codeready Studio+5 | 16/3/2021 | 17/6/2026 | A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system… | |
| Modificada | Media (6.8) | 1.4% | — | Microsoft Azure Container InstancesMicrosoft Azure Container RegistryMicrosoft Azure Kubernetes ServiceMicrosoft Azure Service Fabric+1 | 11/3/2021 | 19/8/2026 | Azure Virtual Machine Information Disclosure Vulnerability | |
| Modificada | Media (6.8) | 2.2% | — | Microsoft Azure Kubernetes Service | 25/2/2021 | 17/6/2026 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | |
| Modificada | Crítica (9.1) | 3.6% | 💥 PoC | Kubernetes Java | 21/1/2021 | 17/6/2026 | Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. | |
| Modificada | Media (6.5) | 2.3% | — | Kubernetes Container Storage Interface Snapshotter | 21/1/2021 | 17/6/2026 | Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically… | |
| Modificada | Media (6.5) | 1.3% | — | Kubernetes Secrets Store CSI Driver | 21/1/2021 | 17/6/2026 | Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes… | |
| Modificada | Media (5) | 9.3% | 💥 PoC | KubernetesOracle Communications Cloud Native Core Network Slice Selection FunctionOracle Communications Cloud Native Core PolicyOracle Communications Cloud Native Core Service Communication Proxy | 21/1/2021 | 17/6/2026 | Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to… | |
| Modificada | Media (5.5) | 1.2% | — | Microsoft Azure Kubernetes Service | 12/1/2021 | 17/6/2026 | Azure Active Directory Pod Identity Spoofing Vulnerability | |
| Modificada | Media (5.5) | 0.53% | — | Kubernetes | 7/12/2020 | 17/6/2026 | In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13. | |
| Modificada | Media (5.5) | 0.52% | — | Kubernetes | 7/12/2020 | 17/6/2026 | In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2. | |
| Modificada | Media (5.5) | 0.46% | — | Kubernetes | 7/12/2020 | 17/6/2026 | In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. | |
| Modificada | Media (5.5) | 0.51% | — | Kubernetes | 7/12/2020 | 17/6/2026 | In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3. | |
| Modificada | Baja (3.5) | 0.25% | — | Redhat Advanced Cluster Management FOR Kubernetes | 23/11/2020 | 17/6/2026 | A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a cluster, they… | |
| Modificada | Media (6.5) | 0.61% | — | Redhat Advanced Cluster Management FOR Kubernetes | 9/11/2020 | 17/6/2026 | An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster… | |
| Modificada | Media (4.3) | 1.1% | — | Jenkins Kubernetes | 4/11/2020 | 17/6/2026 | A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 1.2% | — | Jenkins Kubernetes | 4/11/2020 | 17/6/2026 | A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names. | |
| Modificada | Media (4.3) | 1.3% | — | Jenkins Kubernetes | 4/11/2020 | 17/6/2026 | Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables. | |
| Modificada | Media (5.9) | 0.89% | — | Kubernetes Ingress-nginx | 29/7/2020 | 17/6/2026 | The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name. | |
| Modificada | Alta (8.8) | 3.6% | 💥 PoC | Kubernetes | 27/7/2020 | 17/6/2026 | The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be… | |
| Modificada | Media (5.5) | 0.50% | — | Kubernetes | 23/7/2020 | 17/6/2026 | The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If… | |
| Modificada | Media (6.5) | 1.2% | — | Kubernetes | 23/7/2020 | 17/6/2026 | The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes. | |
| Modificada | Media (6.8) | 6.1% | 💥 PoC | Kubernetes | 22/7/2020 | 17/6/2026 | The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise. | |
| Modificada | Alta (8.8) | 2.3% | — | Jenkins Kubernetes CI | 2/7/2020 | 17/6/2026 | Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. | |
| Modificada | Media (6.3) | 3.7% | — | KubernetesFedoraproject Fedora | 5/6/2020 | 17/6/2026 | The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's… |